A new dashboard counts requests, users and servers, and separately shows the shadow ones nobody approved. It ships for all Zero Trust customers.
- On 14 August Cloudflare announced protocol level detection of MCP traffic.
- There is a new policy selector and a dashboard that also surfaces MCP servers outside approved portals.
- The agents kit moves to the MCP specification dated 28 July 2026.
I know what someone will say: we know what tools we use. Let us look at the dashboard, then we will talk.
Here is what actually changed. Until now MCP was something a developer wires up alone, in ten minutes, and nobody in the company knows. From here it is visible.
We run MCP throughout our own work, which is exactly why I am curious what lands in the shadow column. I will run it and tell you what I saw.
There is no CVE number here and I have not left one out. Nothing was breached; this is a tool for seeing. We keep the rule: a security piece without a CVE gets explained, not glossed over.